Fedora Account System
Red Hat Associate
Red Hat Customer
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled. Upstream patch: https://github.com/jabberd2/jabberd2/commit/8416ae54ecefa670534f27a31db71d048b9c7f16.patch References: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867032 https://github.com/jabberd2/jabberd2/releases/tag/jabberd-2.6.1 http://seclists.org/oss-sec/2017/q3/29
Created jabberd tracking bugs for this issue: Affects: epel-all [bug 1468567] Affects: fedora-all [bug 1468568]
Statement: Red Hat Enterprise Satellite 5 is now in phase 3 of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Satellite 5 Life Cycle: https://access.redhat.com/support/policy/updates/satellite.